Security & trust
The expensive part of healthcare software was never the code — it was the trust: encryption, access control, audit, change control, and the paper trail that proves it all. On this platform that layer is the foundation every tool inherits on day one, not a checklist each tool starts over.
“By default, apps built on the platform persist no patient data — your EHR remains the system of record. Any exception is named, minimal, and approved by you, on the record.”
The platform's standing promise — confirmed app by app, before any build is locked.
Tools fetch patient information on demand while running and let it go; what a tool keeps is its own work-product. If a specific tool genuinely needs to store a patient-linked field, that exception is enumerated field by field, justified, approved by your people on a recorded decision, and encrypted — and your compliance office can read the list any time. There is no shadow chart. There is no second source of truth. A compromised tool finds almost no patient data at rest.
Said carefully, because precision matters here: this posture shrinks risk — it does not exit HIPAA. Displayed chart data is still protected health information in transit, and we treat it that way.
Sensitive data is encrypted at the field level with managed key rotation — not just disk encryption underneath everything.
A hash-chained audit log, immutable at the database level, retained for six years with an archival trail.
Server-side sessions with real revocation, multi-factor authentication, and idle-timeout controls sized for shared clinical workstations.
Organization-based, role-gated access control down to individual capabilities — who can see, who can act, who can approve.
Every product decision your people made — what a tool stores, who sees it, when it went live — recorded with names and dates, exportable, written for a compliance reader.
Compliance documentation mapping the architecture to SOC 2's Trust Services Criteria and the HIPAA Security Rule's technical safeguards, with policy templates and an evidence guide for your auditors.
Your institution's tools run in one application that is yours alone: your own database, your own deployment, no other customer on it. Cross-institution isolation isn't a filter we promise to apply — it's the architecture. The platform surfaces we use to build and operate are kept separate from your instance and hold no patient data at all, ever.
Tools built here run on SOC 2-ready architecture implementing the HIPAA Security Rule's technical safeguards, and we maintain a compliance program to match. SOC 2 is an audit outcome and HIPAA compliance is a property of an operating organization — anyone who tells you their codebase is “HIPAA certified” is selling something. We give your auditors the architecture, the evidence, and the paper trail.
You'll notice this page makes no claims of certification. That's deliberate, and it's the same discipline that runs through every decision card in the product: plain claims, named exceptions, evidence over adjectives.
Every tool moves Preview → Pilot → Live, and each gate is a recorded sign-off by your people — staged, recorded, and reversible. Updates ship on a scheduled release train with a separate emergency lane for security fixes, and your admins see a release log of what changed and when. Scrutiny scales with data sensitivity: a tool that stores nothing patient-linked can take the fast path; a tool holding named patient fields pilots mandatorily.
Your decision log is readable from day one, and if you ever leave, you take your data — every record and your complete decision logs — cleanly exported in open formats. Continuity beyond that is an escrow or exit-license arrangement. Platform-side operational records are erased on the agreement's deletion schedule. We keep customers by being worth keeping.